{"id":"GHSA-mjcr-rqjg-rhg3","summary":"Implementation trusts the \"me\" field returned by the authorization server without verifying it","details":"### Impact\n\nA malicious user can sign in as a user with any IndieAuth identifier. This is because the implementation does not verify that the final `\"me\"` URL value returned by the authorization server belongs to the same domain as the initial value entered by the user.\n\n### Patches\n\nVersion 1.1 fixes this issue.\n\n### Workarounds\n\nThere is no workaround. Upgrade to 1.1 immediately.\n\n### References\n\n- [Security Considerations: Differing User Profile URLs](https://indieauth.spec.indieweb.org/#differing-user-profile-urls-li-1) in the IndieAuth specification.\n\n### For more information\n\nIf you have any questions or comments about this advisory:\n\n* Open an issue in [simonw/datasette-indieauth](https://github.com/simonw/datasette-indieauth/issues)","modified":"2022-03-21T20:04:49Z","published":"2020-11-24T21:21:04Z","database_specific":{"cwe_ids":["CWE-290"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2020-11-24T21:20:38Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/simonw/datasette-indieauth/security/advisories/GHSA-mjcr-rqjg-rhg3"},{"type":"WEB","url":"https://github.com/simonw/datasette-indieauth/commit/376c8804c6b0811852049229a24336fe5eb6a439"},{"type":"PACKAGE","url":"https://github.com/simonw/datasette-indieauth"},{"type":"WEB","url":"https://pypi.org/project/datasette-indieauth"}],"affected":[{"package":{"name":"datasette-indieauth","ecosystem":"PyPI","purl":"pkg:pypi/datasette-indieauth"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.0"},{"fixed":"1.1"}]}],"versions":["1.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/11/GHSA-mjcr-rqjg-rhg3/GHSA-mjcr-rqjg-rhg3.json"}}],"schema_version":"1.9.0"}